Ministerie van Economische Zaken

Senior Information Security Officer (ISO)

13-04-2026
36
13-10-2026
€ Geen max uurtarief
The Hague
24-03-2026
Openbare orde en veiligheid
Freelance

Opdrachtbeschrijving

Doel van de opdracht: Je fungeert als rechterhand van de CISO en beheert de dagelijkse operatie van het Information Security Management System (ISMS). Je vertaalt strategische securityframeworks naar concrete, praktische maatregelen en zorgt dat security structureel is ingebed in de dagelijkse bedrijfsvoering van NEO.

Verantwoordelijkheden

  • Co-managen van het ontwerp en de operatie van het ISMS op basis van ISO 27001.
  • Organiseren en begeleiden van periodieke risicoassessments (bijv. IRAM of ISO 27005) en vertalen van uitkomsten naar prioriteiten.
  • Zorgen dat security wordt meegenomen in architectuur en nieuwe projecten via secure-by-design en secure-by-default principes.
  • Ondersteunen bij de implementatie van wettelijke kaders zoals NIS2 en ISO 27001.
  • Ontwikkelen en onderhouden van praktische securitybeleid, standaarden en richtlijnen.
  • Begeleiden van interne controles, audits en managementrapportages.

Op te leveren resultaten

  • Een volledig operationeel en onderhouden ISMS (ISO 27001-conform).
  • Voltooide en gedocumenteerde periodieke risicoassessments (IRAM/ISO 27005) met duidelijke actieplannen.
  • Ingestelde en verankerde secure-by-design-processen voor nieuwe IT-projecten en architectuur.
  • Volledig ontwikkelde en praktisch geïmplementeerde securitybeleid en richtlijnen.

Eisen

  • Active certification such as CISSP, CISM, CRISC or equivalent are required
  • Proven experience with ISO 27001 (setting up/maintaining an ISMS) and risk
    analysis methodologies (IRAM, ISO 27005 or similar)
  • Completed higher professional (HBO) education
  • Minimum 8 years of experience in information security or cybersecurity
  • Extensive experience with Governance, Risk, and Compliance (GRC) within a
    complex organization

Wensen

  • Experience working within the government, public sector, or other strongly
    governed, complex environments
  • Pragmatic approach; the ability to translate complex security issues into
    workable solutions that fit the scale of the organization
  • Strong advisory skills; the ability to independently prepare decisions,
    structure dossiers, and clearly communicate with both technical specialists
    and management
  • Strong analytical skills and experience with risk management
  • Ability to structure and professionalize security governance
  • Excellent communication skills (bridging the gap between tech and
    management)
  • Independence and a strong sense of responsibility
  • Pragmatic mindset with a focus on workable solutions
  • Organizational sensitivity and administrative insight
  • Experience with ISO 27001 ISMS implementation and maintenance
  • Knowledge of NIS2 requirements and implementation
  • Experience with supply chain security and third-party risk assessments
  • Familiarity with secure-by-design and secure-by-default principles

Competenties

  • Experience working within the government or complex environments
  • Pragmatic approach with strong advisory skills
  • Excellent communication and organizational sensitivity

Vul je gegevens hieronder in, dan nemen we binnen 2 uur contact met je op om samen te kijken of er een match is. Heb je nog vragen? Bel ons op 030-249 66 96 of stuur een e-mail naar info@greenpepper.nl We helpen je graag verder!